i have question about frappe rest api. I hope that this is more about frappe then erpnext. I tried remove access for specific field in Customer doctype. So i setted perm level for this field to 1:

I created user, and setted him role Customer. I setted also role permission.(will attach in second message, dont have perm for more than one images here)
But when i tried make request through rest api (postman), user still can see all fields when accessing through api:
request on: https://www.mydomain.com/api/resource/Customer/?fields=[*]
(will attach in second message, dont have perm for more than one images here)